It wasn't sloppy. It was just luck that someone noticed a half a second extra latency on the second connection of a newly run sshd process and went down the rabbit hole. Had they just shrugged and moved onto more "important" tasks/deliverables, it would most likely have landed in production across the world.
I'm a tad reminded of https://xkcd.com/705/
We got so lucky here. We won't get lucky every time. We will have a massive breach one of these days.